Skip to content

Finance Apps and Privacy: The Four Questions That Actually Matter

Key takeaways

  • Server location and company seat are two different things — both matter, but differently.
  • With a regulated bank connection under PSD2 you pass no login details to third parties.
  • The business model is the most honest privacy indicator: if a service costs nothing, ask how it makes money.
  • The GDPR gives you checkable rights — access, erasure, portability. Use them as a test.
  • Those rights protect you in Germany regardless of your nationality.

“Is this app safe?” is a question nobody can honestly answer with yes — not even the provider. What can be answered are four more concrete questions. They can be checked, against a document every provider has to publish: the privacy policy.

Question 1: Where does the data live?

Two things that are often confused:

The two can diverge: a provider outside the EU can host in the EU, a European provider can use service providers in third countries. The most informative section of any privacy policy is therefore the list of service providers used — hosting, analytics, email delivery, error tracking. It shows where your data actually flows, and it says far more than any wording on the home page.

Question 2: Who has access?

The interesting part here is less the encryption — that is standard — than the organisational side:

Question 3: What happens with a bank connection?

A persistent misconception: “then the app has my login details.” With a regulated connection under PSD2 that is not true. It works the other way round: you authenticate with your own bank and grant consent there. The service then receives limited, revocable read access to your transactions — but no login details.

What it does get is ongoing insight into your transactions for as long as the consent lasts. That is the difference to an import without a bank connection: there is no permanent access there, but you do the updating yourself. Both are legitimate — it is a trade-off between convenience and scope of access, not a question of safe or unsafe. How the connection works technically is described in Connecting your accounts.

Question 4: How does the provider make money?

The most uncomfortable and most useful question. Four common models:

ModelWhat it means for you
SubscriptionThe incentive is keeping you satisfied. Costs money.
AdvertisingAttention is the product; targeting needs data.
ReferralsRecommendations can be commission-driven — that must be clearly labelled.
Selling or analysing dataYour data is the product. Rarely stated this plainly, but it follows from the stated purposes.

No model is dubious in itself. What matters is whether it is named openly and whether its incentives fit what you use the app for.

Your rights — and how to use them as a test

The GDPR gives you three very concrete tools:

These rights apply to you in Germany whatever your citizenship — the GDPR protects people in the EU, not only EU citizens. The practical part: send an email and see what happens. Providers generally have to respond within one month. One that answers evasively or not at all has already answered your privacy question.

What badges do not prove

“GDPR-compliant” on a home page is, as a rule, a self-declaration, not an audited certification. That applies to every app that claims it — ours included. The claim is therefore not proof but a statement that can be checked against the privacy policy. That is what the privacy policy is for.

With sum you can read the four answers instead of trusting them: the data lives on servers in the EU, the company is based in Munich, and the privacy policy lists the service providers used as well as the commitment not to sell your data. Today your transactions come in via CSV import — without permanent access to your account —; the automatic bank connection (PSD2) is in the works.

Frequently asked questions

Are finance apps safe?

That cannot be answered across the board, but it can be checked: where does the data live, who can access it, what exactly is shared with a bank connection, and how does the provider make money. The answers are in the privacy policy — not in a badge on the home page.

Does an app get my bank login details?

Not with a regulated connection under PSD2. You authenticate with your own bank and grant consent there; the service then receives limited, revocable read access to transactions — but no login details.

How do I get my data deleted?

Under Art. 17 GDPR you have a right to erasure, under Art. 15 to access and under Art. 20 to receive your data in a common format. A provider that does not respond within one month has answered your privacy question too.

Is GDPR-compliant a seal of quality?

No. As a rule it is a self-declaration, not an audited certification — that applies to every app that claims it. What is informative instead is the list of service providers in the privacy policy.

Read on


Sources

Frido

Founder of sum · 15 years in finance, CPO and CTO experience.

Updated: 10 September 2026

This article is for information only and does not constitute legal advice.

sum is in early access.

The first step toward your financial goals is the overview — that's exactly what we're building sum for. Secure your access early.